Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

[curriculum-eval] side-quest-17-07-repo-poisoning.md: cognitive_load — 23 security concepts introduced before any worked example

Cerrado Apto para principiantes
#4,309 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
2/5
Tiempo estimado
1-3 horas
Aptitud para principiantes
72/100
Tipo de issue
Documentación
Claridad
Bien especificado
Estado de actividad
Activo
Stack tecnológico
github, markdown, yaml
Área
content

Línea de trabajo

Lee workshop/side-quest-17-07-repo-poisoning.md, centrándote en “The Attack”, “Why This Matters” y “How AW Defends Against It”. Añade el ejemplo solicitado de YAML vulnerable y el ejercicio “Spot the risk”; después, divide las defensas en ejemplos con etiquetas y listas de comprobación breves. La tarea estará completa cuando la lección incluya más comprobaciones prácticas sin añadir prosa sustancial; verifica que el archivo revisado se lea de forma coherente.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

curriculum documentation quality

File: workshop/side-quest-17-07-repo-poisoning.md
Overall Score: 4.95 / 10.0 (corpus mean: 6.09)

Flagged Dimensions:

Dimension Score Benchmark Delta
active_learning 2.7 density ≥ 3 → 10 -7.3
cognitive_load 5.8 ≤800 words, ≤15 concepts → 10 -4.2

Root Cause (≤ 2 sentences):
This security side quest introduces 23 new concepts (permissions scoping, contents: read/write, safe-outputs: create-pull-request, network.allowed-domains, protected-files, branch protection, CODEOWNERS, content-driven manipulation) across 1,234 words of mostly narrative/explanatory prose (the "Attack" and "Why This Matters" sections) before any hands-on application, so cognitive load is high while activity density stays low.

Evidence (quoted from the file):

"Repository poisoning is what happens when a misdirected agent with write access commits changes an attacker designed — not changes the workflow author intended." — this scenario-and-rationale narrative spans roughly 300 words across two full sections before the reader reaches any applied defensive configuration.

Learning Science Rationale:
Sweller's Cognitive Load Theory predicts that introducing many new, interdependent security concepts (permission scoping, safe-outputs, network allowlisting, protected-files, branch protection) in rapid narrative succession without intermediate worked examples overloads working memory capacity (typically 4±1 novel chunks), making it hard for learners to encode the causal chain between "why the attack works" and "which specific field stops it."

Improvement Prompt (for an agent):

Edit workshop/side-quest-17-07-repo-poisoning.md to reduce cognitive load and raise active
learning density. After "The Attack" and "Why This Matters" sections, insert a short worked
example (a 5-10 line YAML code block showing a vulnerable frontmatter snippet with
`contents: write` and no `network.allowed-domains`) immediately followed by a "Spot the risk"
checklist-style micro-exercise asking the learner to identify the dangerous field before
revealing the fix. Split the "How AW Defends Against It" section (which currently introduces
contents:read, safe-outputs:create-pull-request, network.allowed-domains, and protected-files
together) into one labeled code example per defense, each with its own 1-2 item inline
checklist, so code_blocks + checklist_items increases relative to word_count without adding
new prose.

Expected Score After Fix: 6.3-6.8 / 10.0

Generated by 🔬 Curriculum Quality Evaluator · copilot · auto · 96.9 AIC · ⌖ 19.9 AIC · ⊞ 10.4K · ◷

  • expires on Oct 8, 2026, 11:43 PM UTC
Lenguaje dominante
JavaScript
Estrellas
52
Forks
26
Merge medio
12 h 25 min
PR fusionados (30 d)
18

Preparar el entorno

Abrir en Codespaces

Inicia el contenedor de desarrollo del proyecto en tu navegador, con tu propia cuenta de GitHub.

  • Sin Dockerfile ni archivo de Docker Compose
  • Sin plantilla de pull request
  • Sin guía de contribución

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de githubnext/gh-aw-workshop

Todos los issues de githubnext/gh-aw-workshop

Issues similares

Más issues de JavaScript

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.